Ethereum DeFi protocol Ambient Finance lost approximately $110,600 in a smart contract exploit detected by security firm TenArmorAlert. The attacker leveraged a weakness in the protocol's single-contract design, moving stolen funds through other platforms like Uniswap V4. The incident occurred as Ambient's liquidity had already fallen from over $120 million in 2024 to below $2 million, highlighting persistent security risks in the DeFi sector.
Ambient Finance smart contract exploit
▪The security firm TenArmorAlert detected the suspicious attack involving Ambient Finance on the Ethereum network.
▪The exploit targeted a weakness in Ambient Finance's design, which runs all trading activity through a single smart contract.
▪Ethereum DeFi protocol Ambient Finance was exploited, resulting in a loss of approximately $110,600.
Attack execution methodology
▪After the exploit, the attacker's contract received approximately 83.72 ETH, valued at around $140,700, from Ambient Finance.
▪The attack began with a transfer of 50 ETH, worth about $84,000, into a newly created smart contract.
▪The attacker used Titan Builder, a transaction execution service, suggesting an attempt to optimize transaction execution after the exploit.
Cross-protocol fund movement
▪The attacker split the funds into smaller transactions and moved them across different platforms to reorganize the assets.
▪The attacker moved a portion of the stolen funds through the decentralized exchange Uniswap V4.
▪Following the exploit, the stolen funds were converted into Wrapped Ether to be used across DeFi systems.
Ambient Finance protocol decline
▪The protocol's liquidity fell from a range of $120 million to $130 million in 2024 to below $2 million by 2026.
▪Data from DefiLlama shows Ambient Finance has annualized fees near $376,000 and reported revenue of zero.
▪Ambient Finance, formerly known as CrocSwap, currently holds about $1.88 million in total value locked (TVL), according to DefiLlama.
DeFi security exploits
▪Wasabi Protocol recently lost over $5 million after attackers gained access to one of its administrative keys.
▪In January 2026, attackers stole over $17 million from SwapNet and Aperture Finance contracts.
Story comments
Loading comments…